cbcvebase.
CVE-2019-6172
published 2019-11-12

CVE-2019-6172: A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad…

PriorityP429medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.33%
25.4th percentile
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

Affected

11 ranges
VendorProductVersion rangeFixed in
lenovothinkpad>= Various < VariousVarious
lenovothinkpad_helix_firmware< gfet65wwgfet65ww
lenovothinkpad_s531_firmware< gket46wwgket46ww
lenovothinkpad_t440_firmware< gjeta3wwgjeta3ww
lenovothinkpad_t440p_firmware< gleta0wwgleta0ww
lenovothinkpad_t440s_firmware< gjeta3wwgjeta3ww
lenovothinkpad_t540p_firmware< gmet89wwgmet89ww
lenovothinkpad_w540_firmware< gnet92wwgnet92ww
lenovothinkpad_w541_firmware< gnet92wwgnet92ww
lenovothinkpad_x240_firmware< giet98wwgiet98ww
lenovothinkpad_x240s_firmware< giet98wwgiet98ww

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.